[TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3

Eric Rescorla <ekr@rtfm.com> Wed, 06 May 2026 19:44 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 0CA20EA20ABA for <tls@mail2.ietf.org>; Wed, 6 May 2026 12:44:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1778096688; bh=DB9LGOGfeFQ+GUdamuCZofFda5F1ortm13Rq6cLJ5QY=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=WnLbhS1FjXZsVKhML1X5Ma6NipF76JjUU6wg2fL3Ib/Yxr7fQGFp5zCLyW8xowL76 YXyZDvR9ltG4xNoGyDqkgEOCFDZLcnsk96aDieQdszp+fGYR/+h3hIQ5oRhvOpxVOT 4NwGDjHRNEUMxkr11qwTAgCd8rl6+0Jd1pOsmR9Q=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.797
X-Spam-Level:
X-Spam-Status: No, score=-1.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20251104.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cr3Z4lHaJwOf for <tls@mail2.ietf.org>; Wed, 6 May 2026 12:44:43 -0700 (PDT)
Received: from mail-yx1-xb133.google.com (mail-yx1-xb133.google.com [IPv6:2607:f8b0:4864:20::b133]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id C4455EA20AB3 for <tls@ietf.org>; Wed, 6 May 2026 12:44:43 -0700 (PDT)
Received: by mail-yx1-xb133.google.com with SMTP id 956f58d0204a3-65c37eafcbeso25500d50.1 for <tls@ietf.org>; Wed, 06 May 2026 12:44:43 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1778096683; cv=none; d=google.com; s=arc-20240605; b=dHSdIhN+6TQhyx2Sgk8bqgdXoRKBR3HE7vRXMrXrGunb3mBlXj4NlCwcG7M+drHwH/ F/WraFRmxJ1hGYvOdWbkAROqZOOwFd5b3gTrTYZ55rnkDIbjk0STbE7ECDkFRBwFP9fG jgYRXoNT3L9K8SGUXWM7h5Ce/k/ZhZKmfV/f2ZWlkS5qDEhh76K1tlKdwZoxOG19NzXd s+3Mske2F+npyGoJ6WfdHxPoJUnd9VWj5RGyHcnsH+bj0RRvz8g6uC0DhUV5QeudqUtK N07mGv0A5L6OkZ1cj7sN8MxblEiBorCnY7nv2dJxUZPCSIo+ei0/uCN/hiOWAuJ8qy5o YiqA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=kut4cjrNOnUhez06+A094Q6sI61Lg4xYOPAE2jh0JSs=; fh=ecxAV+zbXDjLlDmK7zvb+srElCv8RDgPlMF5rxNnMJ4=; b=az5mSVCcPUMbXxMc9Vgrn2nOj0si3f0G6YNIX0zOGfWMVz1tG4ZbwGPIUzLqvuakXn Xn6KWCb01M9o5kg0+lP5yQ7QZcGxS6Kirewzc6gwOGSpaojkXg7IY+BQCngJ6nbw76iA QRvnOGUGgDEYE9XkbYfnDWtSSX78d/R85QYCNhGngmzA2W1eN0Ueml78tM9IIbf8tgql LsMSyYrWPBn+vQuP0/D3VfW/4uQAKkjZZU2BBcaY0JcmLixZfUIJyd+st5urxztxkRg6 oAqqG/hADTQuqKWJt40HiIK16FwS2KYeQYhU/F8WHeqCIS2JgIpGZQ9RdYwbFY8nC5SD wKHA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20251104.gappssmtp.com; s=20251104; t=1778096683; x=1778701483; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=kut4cjrNOnUhez06+A094Q6sI61Lg4xYOPAE2jh0JSs=; b=WEEguFCiQlbh9MkMqtM/clTLufhiozV/bvUDjUDovhGnZvSBsFwBrankGrSjaC5+Pv /8ROemzNdagzWYHQGBMlnFQwI/q2rbM39vOt580SJutqGSo5rWcj62oLtlmpw9Mi4jEs Qv/xKLYkgt8mAk9iZX9o0N6yWSHnU8921+f8GrV62exn7Yjd29KOksU3TDznQfY/ZnuE SHDZOhP+F0C5QprHJiKEhEGRjcxuaHgT6HB4u0gBATCuk997rkGtJV5KU5STDhInRMXz xCxsWVMk06g+kQvfj3mIbvW57hAqA4TPaYyCEZjaOsQALNVKCn7v2tjiVRUZnIxGdQ1Z jkqQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1778096683; x=1778701483; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=kut4cjrNOnUhez06+A094Q6sI61Lg4xYOPAE2jh0JSs=; b=gLB/VYKtiX6Bpk1l0c0By/43BPAOSxUTcSdmbRXdZpMZG13j5nKcT2vlrwoukFRmt0 unU6gYs9upHqNChZuw7mxI8J4pVTC08XFkOMkeXTwGOZHymA19ZCHPV5tkKkCdrVvQMY lvjHj6uG0GjocMXvgpIyn+ErNDdzuseLeCebLSgELFijCkRiRYsTJQqIJhvgYdu9RzBm xVHsO+5LGPem23qG1YR6AYXPRG8DOSOWnaU9f6TjRmWeGUzm5DM+Fw1UxZkIDMlsLo3p d0Qj0sWPA3fI+87ilM/KMnLRcClqh6v9NFYiBNqAzQCLZxsG81QcpUqycshJaVzoTFKo HoKg==
X-Forwarded-Encrypted: i=1; AFNElJ9exbuxjfaaTBo1m5frN/rNMNTgKv+1tBkoT7dws/TfiyOOeDooFmSmQfq1cJ6vaEIGXGs=@ietf.org
X-Gm-Message-State: AOJu0YzLkrn6lqYm9D5V/kXC7Jpon0q5ASRA3DJGeZc+srAsnjJeGn5M hn5e6f53dxn3e1yFhjr6cmWjXvJmfo0G8S+Gbz9ddiEbGlB3o1DTAe1pL6r9AZdK2LFP3x6xhQa h4thMAbWx69V3uFruhB6bXv8c+wcnfXokpSbQm+S4nwolxy+XCK0U
X-Gm-Gg: AeBDiesytkiu2D6mI1kO5+SvGfBRcekDrhZPeRhajNr+MP1Eu9SVT8WvI2TGsuqr3yX LdxTc9I45u6LdZu4D0mAoj2yj15mjO1ltThSvCO3UxRx2d18XnJdxMje8LPQaeFmHrDi8+aaEL5 +PRXRNNDNZ+VesiFMqTOQJF0sztE9aPn/LJdhLQApOll5Mx42SAA9kiS7FHQbg81Bu6qo+kLbxm SEs8qcvcJFCB4f3ME0vAJzaQDZPjDBDKUBJ96SwboJJ1McSNR04sTNlZmSnaEGQ/JB/VnmUcwj7 8r8fRq/HFXwqjKeZheA6dwvWx2on4Fhb9sci4MhLxOUgix8okqDVDhrR87IjVPnygDQ2YTdHfTG 41Fmj4/riltNzx9//Ws7/iYtWTahFYnT8
X-Received: by 2002:a05:690c:398:b0:7bd:7d69:764b with SMTP id 00721157ae682-7bdf5edf439mr55684817b3.39.1778096683187; Wed, 06 May 2026 12:44:43 -0700 (PDT)
MIME-Version: 1.0
References: <16CF0FDA-7263-461A-9F2B-D37DBEAF5DD9@sn3rd.com> <038E2DBD-EE06-4091-8401-9818FB692459@sn3rd.com> <3E4481D4-A20E-4B3B-B5BE-B71BBDA42176@sn3rd.com> <CAF8qwaBU3-VvY2TregAg7VezK6b4dmOUTsEFNmq=zj1eMoPgHQ@mail.gmail.com> <CABcZeBNzQ3-qQgQCpEigo9cVRZNQScO3cB+QEvjuNJ-xP_fQGw@mail.gmail.com> <BYAPR14MB288524DF36A25332DC1FA6E6D73F2@BYAPR14MB2885.namprd14.prod.outlook.com>
In-Reply-To: <BYAPR14MB288524DF36A25332DC1FA6E6D73F2@BYAPR14MB2885.namprd14.prod.outlook.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Wed, 06 May 2026 12:44:05 -0700
X-Gm-Features: AVHnY4Ik9dQ1LcmdCpzAqN-jg1GTS5C81WrMeHEDcrS4XhsDlbjKEXnvCinDOeQ
Message-ID: <CABcZeBNXNgRd19duGLa5wAC=PWkmqhK3+2+t0WrYzqkz+dVAhQ@mail.gmail.com>
To: "Ackermann, Michael" <MAckermann@bcbsm.com>
Content-Type: multipart/alternative; boundary="0000000000002d8c3206512b656b"
Message-ID-Hash: ZAFPUCU6ZUEOGJJ5YRFDSBYU2R3PW7WC
X-Message-ID-Hash: ZAFPUCU6ZUEOGJJ5YRFDSBYU2R3PW7WC
X-MailFrom: ekr@rtfm.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/jJcZkeTarGu3dES67hVWQvsC1qM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Not sure what you're talking about here, Michael. Can you explain?

-Ekr


On Wed, May 6, 2026 at 12:36 PM Ackermann, Michael <MAckermann@bcbsm.com>
wrote:

> HOSTILE TAKEOVER???????????
>
>
>
> *From:* Eric Rescorla <ekr@rtfm.com>
> *Sent:* Wednesday, May 6, 2026 12:51 PM
> *To:* David Benjamin <davidben@chromium.org>
> *Cc:* TLS List <tls@ietf.org>
> *Subject:* [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
>
>
>
> [External email]
>
> +100 to this.
>
>
>
> With any luck, we can take a pause on the discussion of this topic
> on-list. I am aware that there may be pending appeals, but we have a
> process for addressing those that does not require on-list debate.
>
>
>
> -Ekr
>
>
>
>
>
> On Wed, May 6, 2026 at 6:23 AM David Benjamin <davidben@chromium.org>
> wrote:
>
> Thanks, Deirdre, Joe, and Sean, for all your hard work in navigating these
> WG discussions!
>
>
>
> On Wed, May 6, 2026 at 9:09 AM Sean Turner <sean@sn3rd.com> wrote:
>
> Replying to the original consensus call message.
>
>
>
> RFC 2418 Section 3.3 lays out the criteria for “rough consensus”:
>
>
>
>    Working groups make decisions through a "rough consensus" process.
>
>    IETF consensus does not require that all participants agree although
>
>    this is, of course, preferred.  In general, the dominant view of the
>
>    working group shall prevail.  (However, it must be noted that
>
>    "dominance" is not to be determined on the basis of volume or
>
>    persistence, but rather a more general sense of agreement.) Consensus
>
>    can be determined by a show of hands, humming, or any other means on
>
>    which the WG agrees (by rough consensus, of course).  Note that 51%
>
>    of the working group does not qualify as "rough consensus" and 99% is
>
>    better than rough.  It is up to the Chair to determine if rough
>
>    consensus has been reached.
>
>
>
> In this case, during WGLC there was an almost 4:1 ratio for progressing
> this draft, which we judge fits within the numeric “more than 51% and less
> than 99%” range suggested by this text for “rough consensus” and represents
> the “dominant view of the working group”.
>
>
>
> In assessing rough consensus, we also considered the nature of the
> objections. In reviewing the list traffic, the majority of objections
> related to the status of pure MLDSA versus composite MLDSA-ECC, including
> (1) we should not publish a pure MLDSA specification at all; (2) we should
> recommend composites over pure MLDSA; (3) we should publish the composite
> and pure MLDSA specifications concurrently. While there was substantial
> disagreement on these points, we believe that the discussion on-list
> sufficiently aired the respective points of view and that the right
> approach is fundamentally a judgement call based on weighing various
> technical factors, which each WG participant needs to make for themselves.
> We see no reason to believe that participants were not able to make
> informed judgements.
>
>
>
> Conclusion: The chairs believe there is consensus to proceed with
> publication of this draft as an RFC with Recommended=N for those people
> that want to use this algorithm, and a future Standards Action will be
> needed to make a change to Recommended=Y, if anyone has the willingness to
> undergo this heated discussion again.
>
>
> For transparency purposes, the chairs note that we received a
> complaint/appeal about the consensus call. The message was moderated due to
> a previous notice of moderation; see [1], and the complaint/appeal contains
> a derivative work notice. As a result, the message was not sent to the mail
> list and we will not process the complaint/appeal as-is. If the message is
> resubmitted without the notice, the message can be posted to the mail list
> and we will process the complaint/appeal.
>
>
>
> The Chairs,
>
> Deirdre, Joe, and Sean
>
> [1] https://mailarchive.ietf.org/arch/msg/tls/no0lW8r_wIPGF1ZXWB3EaGywh9Q/
> <https://urldefense.com/v3/__https:/mailarchive.ietf.org/arch/msg/tls/no0lW8r_wIPGF1ZXWB3EaGywh9Q/__;!!DVqnNCPqsA!H9Py_Rt__O8pjzUI4OMX2OusR6HFRbXek-Wm9dHUdjLkLaTuW7-CKZAvUaDoN8M1vUJ4yLIQHQ$>
>
>
>
> On Apr 28, 2026, at 16:24, Sean Turner <sean@sn3rd.com> wrote:
>
>
>
> Hi! The chairs have judged that there is consensus to progress this I-D.
> We will work with the authors to get a new version submitted and we will
> get to work on the Shepherd Write-Up.
>
>
>
> The Chairs,
>
> Deirdre, Joe, and Sean
>
>
>
> On Apr 9, 2026, at 15:30, Sean Turner <sean@sn3rd.com> wrote:
>
>
>
> This is the working group last call for Use of ML-DSA in TLS 1.3. Please
> review draft-ietf-tls-mldsa [1] and reply to this thread indicating if you
> think it is ready for publication or not. If you do not think it is ready
> please indicate why. This call will end on April 23, 2026.
>
> REMINDER: If you have not done so recently, review the TLS WG's Mail List
> Procedures; see [2].
>
> The Chairs,
> Deirdre, Joe, and Sean
>
> [1] https://datatracker.ietf.org/doc/draft-ietf-tls-mldsa/
> <https://urldefense.com/v3/__https:/datatracker.ietf.org/doc/draft-ietf-tls-mldsa/__;!!DVqnNCPqsA!H9Py_Rt__O8pjzUI4OMX2OusR6HFRbXek-Wm9dHUdjLkLaTuW7-CKZAvUaDoN8M1vUKcrqJCBA$>
> [2] https://mailarchive.ietf.org/arch/msg/tls/ucdImHExlbOf4Q3BCG81gjzi2xE/
> <https://urldefense.com/v3/__https:/mailarchive.ietf.org/arch/msg/tls/ucdImHExlbOf4Q3BCG81gjzi2xE/__;!!DVqnNCPqsA!H9Py_Rt__O8pjzUI4OMX2OusR6HFRbXek-Wm9dHUdjLkLaTuW7-CKZAvUaDoN8M1vUJmOlAILQ$>
>
>
>
>
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>
> The information contained in this communication is highly confidential and
> is intended solely for the use of the individual(s) to whom this
> communication is directed. If you are not the intended recipient, you are
> hereby notified that any viewing, copying, disclosure or distribution of
> this information is prohibited. Please notify the sender, by electronic
> mail or telephone, of any unintended receipt and delete the original
> message without making any copies.
>
> Blue Cross Blue Shield of Michigan and Blue Care Network of Michigan are
> nonprofit corporations and independent licensees of the Blue Cross and Blue
> Shield Association.
>